A citizen of Hyderabad has been defrauded of Rs8.5 million through a duplicate SIM card, it emerged on Thursday.
The victim, identified as Sunny Kumar, lodged a complaint with the National Cyber Crime Investigation Agency (NCCIA), stating that on September 29, 2025, between 7 and 8 pm, he was in Karachi when his SIM card suddenly stopped working.
The next day, September 30, he visited a mobile company’s business center in Karachi where he was informed that a duplicate SIM had been issued in his name in Hyderabad without his biometric verification. The same SIM number was linked to his bank account.
The citizen revealed that when he checked his bank account, he found that through fraudulent means, an amount of 8.5 million rupees had been withdrawn in a single night via over 100 transactions and transferred to multiple different accounts.
NCCIA officials said that the citizen provided evidence, following which requests were made to the private bank and the cellular company for relevant records. However, both failed to provide the required information.
Officials said that the relevant bank branch manager was summoned along with all related records. Instead of the branch manager, the bank sent a relationship manager who provided only the affected citizen’s bank statement and partial transaction records. After being instructed to provide additional documentation, the bank failed to submit the full requested records.
Officials further said that records were also requested from the head of compliance of the cellular company. Despite multiple reminders, the company gave vague and unsatisfactory responses. Later, the cellular company’s manager of franchise services and governance and senior executive of government relations and regulatory affairs appeared and submitted partial records.
According to officials, they asked 48 questions related to SIM issuance, security measures, accountability, device location tagging, and BVSS SOPs, but the officials refused to answer and requested more time to submit a written response with the remaining documents.
Officials said that the transaction pattern indicates a planned cyber financial fraud involving SIM swap activity followed by unauthorized access to the complainant’s digital banking system.
They added that criminal negligence in reissuing the SIM directly facilitated fraud on the complainant’s bank account, while the bank failed to exercise due diligence.
Officials said that despite biometric login access, OTP verification, and anti-fraud monetary mechanisms, the bank allowed multiple high-value transactions within a few hours without proper verification on red flag alerts.
They concluded that unauthorized access to the complainant’s digital banking system was granted through the SIM fraudulently obtained via SIM swap.















